ios-design-brief

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard iOS development and automation tools including xcodebuild, xcrun simctl, and the axe accessibility/automation CLI. These are used locally to manage simulators, build the application, and capture screenshots for visual analysis.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is instructed to ingest and analyze untrusted data from docs/PROJECT-BRIEF.md and visual content from captured application screenshots. This is a functional requirement for its design analysis purpose.
  • Ingestion points: docs/PROJECT-BRIEF.md, CLAUDE.md, and .design/*.png screenshots.
  • Boundary markers: Absent; the agent reads the files and images directly without specific delimiters.
  • Capability inventory: Shell execution (xcodebuild, xcrun, axe) and local file writing (docs/DESIGN-SYSTEM.md).
  • Sanitization: No explicit sanitization or instruction filtering is mentioned.
  • [SAFE]: All identified operations are aligned with the skill's primary purpose of iOS design system generation. The use of local developer tools and file access is standard for this use case and no indicators of data exfiltration, obfuscation, or persistence were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 01:51 AM
Security Audit — agent-trust-hub — ios-design-brief